Shadow AI: What It Is, Real Examples, and How to Detect It

Shadow AI: What It Is, Real Examples, and How to Detect It

Shadow AI: What It Is, Real Examples, and How to Detect It

Category:

AI Visibility

Shadow AI Risk

Published date:

Key Takeaways

  • The average enterprise runs 14 AI tools. IT can name four or five. You are governing about one tool in three.

  • 73.8% of enterprise ChatGPT use runs on personal accounts, and 82.8% of the sensitive data entering AI tools travels through them.

  • Your existing stack cannot see it. SaaS management indexes invoices, endpoint security indexes binaries, cloud tools index cloud accounts. Shadow AI is free, browser-based and inside the IDE.

  • Shadow-AI-related breaches cost $670,000 more on average, and 97% of organisations breached through AI had no AI access controls at all.

  • Guickly discovers every AI tool, user and dollar across SaaS, cloud and the IDE, using metadata only. It turns the number in your board deck into the real one.

Shadow AI is any AI tool, model, or agent used inside a company without IT approval, inventory, or budget. It includes free ChatGPT and Claude accounts, IDE coding assistants, AI features switched on inside approved SaaS, and browser extensions that send prompts to third-party models. Most enterprises run roughly three times more AI than IT can see.

Your IT team can probably name five AI tools running in your company. The real number is closer to fourteen. That gap is not a rounding error. It is the difference between the AI you govern and the AI quietly processing your source code, your customer data and your board memos on accounts nobody has ever seen.

This is the CIO problem of 2026. The AI you did not buy is bigger than the AI you did.

Shadow AI by the numbers


Finding

Figure

Source

AI tools in the average enterprise

14, while IT knows of 4 to 5

Productiv

Enterprise ChatGPT use on personal accounts

73.8%

Harmonic Security, 22.4M prompts analysed

Sensitive data entering AI through shadow accounts

82.8%

Harmonic Security

Extra cost of a shadow-AI-related breach

$670,000 above average

IBM Cost of a Data Breach 2025

Breaches where shadow AI was a factor

20%

IBM, 2025

Breached organisations with no AI access controls

97%

IBM, 2025

Employees bringing their own AI tools to work

78%

Microsoft and LinkedIn Work Trend Index

What is shadow AI?

Shadow AI is any AI tool, model or agent running inside an enterprise that has not been sanctioned, inventoried or budgeted.

Same shape as shadow IT. Very different velocity. Shadow IT took a decade to compound. Shadow AI compounds every quarter, because the barrier to starting is a browser tab and no purchase order.

What are examples of shadow AI?

Five categories cover almost everything we see:

Free-tier consumer accounts. ChatGPT, Claude and Gemini logins created with a work email or a personal one. No contract, no data agreement, no visibility.

IDE coding assistants. Cursor, Windsurf, Copilot and Cline running on developer laptops. Thousands of model calls per developer per day. In most engineering organisations this is now the single largest AI surface, and the one the stack sees least.

AI inside SaaS you already approved. Notion, Slack, Zoom and Salesforce all shipped AI features recently, most switched on by default. They do not register as an AI tool in your inventory. They register as the tool you approved last year.

Browser extensions. Summarisers, writing assistants and meeting bots that quietly route page content and transcripts through third-party models.

Self-provisioned agents. Single-purpose agents an employee spins up on a personal card to automate part of their own job. Useful, invisible, and completely ungoverned.

How big is shadow AI, really?

Bigger than the number in your last board deck, and the inversion is the point.

Most CIOs were handed the same question last quarter: what AI are we actually using? Most answered with a sanctioned vendor list, a Copilot seat count and the enterprise ChatGPT contract. That answer describes the tip.

Productiv found the average enterprise runs 14 distinct AI tools while IT is aware of four or five. Harmonic Security analysed 22.4 million enterprise AI prompts and found 73.8% of ChatGPT use ran through personal, non-corporate accounts. Not 7%. Not 17%. Nearly three out of four prompts.

So the picture flips. The sanctioned stack you report to the board is the minority of the AI in your building. The majority is shadow.

Why doesn't our existing software stack detect shadow AI?

Because every tool you own indexes on the wrong thing.


Your existing tool

What it indexes by

Why it misses shadow AI

SaaS management

Invoices

Most shadow AI is free at the point of use

Endpoint security

Installed binaries

Browser-based AI installs nothing

Cloud cost tools

Cloud accounts

Consumer AI never touches your cloud

SSO and identity

Provisioned logins

Personal accounts bypass SSO entirely

DLP

Known channels

Prompts leave through the browser, uninspected

Shadow AI lives in the gaps between all five. Three things make the real footprint balloon past the reported one.

It is mostly free at the point of use. A free ChatGPT tab, a personal Claude login, a no-cost extension. None of it hits procurement, so none of it appears on the list procurement keeps.

It is bundled into tools you already trust. See the SaaS point above. The AI arrived inside software that already passed review.

It hides inside the IDE. Coding assistants never touch your SSO, rarely touch finance and never show up in a SaaS audit.

What are the risks of shadow AI?

Start with the breach maths, because that is the number a board reacts to. IBM's 2025 Cost of a Data Breach report found shadow-AI-related breaches cost $670,000 more on average. Shadow AI was a factor in 20% of breaches studied. 65% of those involved customer PII. And 97% of the organisations breached through AI had no AI access controls in place when it happened.

But the breach is the end of the story. The leak starts earlier and much more quietly. Every prompt typed into a personal account leaves your environment and lands with a third party you have no contract with. Harmonic found 82.8% of sensitive data going into AI tools travelled through exactly these accounts. The most exposed categories: source code at roughly 30%, legal documents at 22%, M&A material at 13%. That is your codebase, your contracts and your deal pipeline, pasted into a free tab to clean something up quickly.

It has already happened in public. Within 20 days of allowing ChatGPT, Samsung engineers had pasted semiconductor source code and internal meeting notes into it, and the company banned the tool outright. The pattern never changes. The data leaves before anyone knew the tool was in use.

There is a second cost, quieter than the first. Shadow AI is unbudgeted spend. It shows up as a growing line item nobody owns, which means finance cannot forecast it and nobody can optimise it.

How do you detect shadow AI?

You cannot govern what your SSO cannot see, and you cannot inventory by survey. People underreport, and the fastest-growing surfaces are the ones employees do not even think of as tools.

Four approaches, in ascending order of how much they actually find:

Ask people. Anonymous surveys surface some usage and cost nothing. They also miss most of it, because employees do not classify a browser extension as an AI tool.

Read your identity logs. SSO and IAM logs show sanctioned access patterns. Useful, and blind to every personal account.

Inspect the network. SASE and secure web gateways see traffic to known AI domains. Good coverage of consumer web AI. No spend attribution, no view of what it returned.

Watch the endpoint. Discovery at the device level catches what the other three miss, including IDE assistants and embedded SaaS AI, because that is where the calls actually originate.

The durable answer asks a different question than your existing stack. Not "what did we buy" but "what AI is being called in our environment, by whom, against which model, and at what cost." Guickly was built to answer that question across SaaS, cloud and the IDE in one view, using metadata only. We never see your prompts or your responses.

How is shadow AI different from shadow IT?

Shadow IT was about software bought outside procurement. The fix was a purchase-order policy.

Shadow AI is about capability flowing through tools you already bought, IDEs you already issued and cloud accounts you already approved. The surface is wider, the velocity is faster, and each call may carry customer or proprietary data to a third-party model. A purchase-order policy cannot see any of it.

The board is going to ask. Know the real number first.

The CIOs who win the next 18 months will not be the ones with the boldest AI strategy. They will be the ones who can state the real footprint, sanctioned and shadow, without flinching.

Lead with the inventory, not the roadmap. Report the count of AI tools detected, the split between sanctioned and shadow, the spend mapped to each, the departments with the highest concentration, and the data classes being processed. Then layer the plan on top. Boards trust the leader who leads with a number.

The honest number is bigger than the one in your last deck. Better that you are the one who finds it.

FAQ

What is shadow AI? Shadow AI is any AI tool, model or agent used inside a company without IT approval, inventory or budget. It includes free-tier LLM accounts, IDE coding assistants, AI features auto-enabled inside approved SaaS, browser extensions that route prompts to third-party models, and single-purpose agents employees provision themselves.

What are examples of shadow AI? Free ChatGPT, Claude or Gemini accounts used for work. Coding assistants like Cursor, Copilot, Windsurf and Cline on developer laptops. AI features switched on by default in Notion, Slack, Zoom or Salesforce. Browser extensions that summarise pages or transcribe meetings. Agents an employee builds and pays for on a personal card.

How big is shadow AI? Productiv found the average enterprise runs 14 AI tools while IT knows of four or five. Harmonic Security found 73.8% of enterprise ChatGPT use runs on personal accounts. Microsoft's Work Trend Index found 78% of employees bring their own AI tools to work. IT typically sees about one AI tool in three.

How do you detect shadow AI? Four methods, in increasing order of coverage: anonymous employee surveys, identity and SSO log review, network-level detection through SASE or a secure web gateway, and endpoint-level discovery. Endpoint discovery finds the most, because it catches IDE assistants and SaaS-embedded AI that never appear in invoices, network logs or SSO.

Why doesn't our existing software stack detect shadow AI? Because SaaS management indexes by invoice, endpoint security by installed binary, and cloud cost tools by cloud account. Most shadow AI is free at the point of use, embedded in SaaS you already approved, or running inside the IDE. It falls in the gaps between those systems and often never generates an invoice at all.

What are the risks of shadow AI? Data exposure first. Prompts sent through personal accounts leave your environment for a third party you have no contract with. Harmonic found 82.8% of sensitive data entering AI tools went through shadow accounts, most commonly source code, legal documents and M&A material. IBM found shadow-AI-related breaches cost $670,000 more on average, and 65% of them involved customer PII. The second risk is unbudgeted spend that finance cannot forecast.

How much does shadow AI cost? Two ways. Directly, as unbudgeted spend on tools nobody owns, typically 20% to 40% of real AI spend sitting outside the visible budget. Indirectly, through breach risk: IBM put the shadow-AI premium at $670,000 per breach in 2025.

How is shadow AI different from shadow IT? Shadow IT was software bought outside procurement, solved with purchase-order policy. Shadow AI flows through tools you already bought, IDEs you already issued and clouds you already approved. It is wider, faster, and every call can carry proprietary data to a third-party model.

Can you block shadow AI? Blocking alone tends to fail, because employees route around it and you lose the productivity along with the risk. The pattern that works is to discover everything first, then bring high-value tools under sanctioned accounts with proper data terms, and block only what is genuinely unsafe. Visibility comes before control.

Your AI transformation

starts with visibility.

See every AI tool. Track every dollar. Control every budget. Optimize every call. One platform, live in under an hour.

GUICKLY

The AI Transformation Platform

Guickly gives enterprises complete visibility and control over their AI transformation from adoption through optimization. Trusted by teams that are AI-first.

©2026 Guickly. All rights reserved.

Your AI transformation

starts with visibility.

See every AI tool. Track every dollar. Control every budget. Optimize every call. One platform, live in under an hour.

GUICKLY

The AI Transformation Platform

Guickly gives enterprises complete visibility and control over their AI transformation from adoption through optimization. Trusted by teams that are AI-first.

©2026 Guickly. All rights reserved.

Your AI transformation

starts with visibility.

See every AI tool. Track every dollar. Control every budget. Optimize every call. One platform, live in under an hour.

GUICKLY

The AI Transformation Platform

Guickly gives enterprises complete visibility and control over their AI transformation from adoption through optimization. Trusted by teams that are AI-first.

©2026 Guickly. All rights reserved.